MALICIOUS
66
Risk Score
Malware Insights
MITRE ATT&CK
T1566.001 Spearphishing Attachment
T1059.007 JavaScript
This PDF document was flagged as malicious by an ML classifier. The file embeds a large number of external links characteristic of an SEO link farm. Specific URLs and indicators for this sample are listed in the indicators section.
Machine Learning
- Nyx PDF Classifier malicious score 0.9998
Heuristics 4
-
Small PDF is a non-clustered link farm on disposable hosting medium PDF_SEO_DISPOSABLE_LINK_FARMSmall PDF contains many clickable external PDF links spread thin across many distinct hosts (no single dominant host), corroborated by a utm_term SEO-redirector link and/or links parked on free/disposable content hosts. This is the 'free document/template' SEO phishing PDF family, which ranks for search queries and routes users into payload/redirect chains, rather than a normal document citation pattern. The PDF itself carries no exploit — the risk is the linked destinations.
-
External URI info PDF_URIPDF contains an external URL action
-
Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTALThe same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
-
Embedded URL info EMBEDDED_URLOne or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.URL https://golowaki.ru/123?utm_term=standard+aluminium+sheet+metal+thickness PDF link annotation
- http://fokefetebebinin.66ghz.com/72117540638.pdfIn PDF document text
- http://zozegakipuvi.iblogger.org/shrimad_bhagavad_geeta_in_gujarati_download.pdfIn PDF document text
- http://nomevufaneboja.mypressonline.com/dabafakufusoloxumawigiga.pdfIn PDF document text
- http://guditoresuz.22web.org/bokeh_effect_png.pdfIn PDF document text
- http://xiwupulo.medianewsonline.com/affinity_designer_tutorial_italiano.pdfIn PDF document text
- http://www.ascendercorp.com/In PDF document text
- http://www.ascendercorp.com/typedesigners.htmlIn PDF document text
- https://994180ce-385f-4272-9833-4a204a825e0f.filesusr.com/ugd/ec0c41_be610f12655a4203bcee71ab7ceb87dd.pdf?index=trueIn PDF document text
- https://dab7fb03-f2af-4a8e-9cb9-31de623bedb3.filesusr.com/ugd/58b596_ee46c2bf02424ae6a4f32d6bb4f3c304.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/tevigotu/yellow_coldplay_drum_sheet_music.pdfIn PDF document text
- https://3ea853e4-7f2b-4fb0-9229-b04907a1e321.filesusr.com/ugd/d94095_6a0b5dd4d9c145bfa0f9543fb1713254.pdf?index=trueIn PDF document text
- http://kotumeberi.rf.gd/jukaxumegesife.pdfIn PDF document text
- http://sinejelubomidi.epizy.com/91107666959.pdfIn PDF document text
- http://virafesejasaxi.rf.gd/bixufakapixekaji.pdfIn PDF document text
- https://s3.amazonaws.com/zusevamasor/arifureta_shokugyou_de_sekai_saikyou_light_novel_volume_10.pdfIn PDF document text
- http://depesup.epizy.com/jotamafosuruvopi.pdfIn PDF document text
- https://72858ab8-d36f-4bc2-b208-e5ec56e76d01.filesusr.com/ugd/3a4e0e_295f252aabe24e46b82d8d897e60f8b9.pdf?index=trueIn PDF document text
- https://93641f3c-03d3-4c8c-b6db-0fd9bfabe798.filesusr.com/ugd/384ca7_0e4d2ce61c194e908e5c6eb53fcb8acb.pdf?index=trueIn PDF document text
- https://4e4608fd-868e-43f5-b6ba-14e5e4b50785.filesusr.com/ugd/b1f235_0d92aa61ff2f4681bcc40444b092a79a.pdf?index=trueIn PDF document text
- https://c46c713f-5e69-4c64-aad4-d86f29440f76.filesusr.com/ugd/957c7b_15ea3ab652c147c2a7e6726e9d7fd087.pdf?index=trueIn PDF document text
- https://s3.amazonaws.com/pasawe/cx500_service_manual.pdfIn PDF document text
- http://www.w3.org/1999/02/22-rdf-syntax-ns#In PDF document text
- http://purl.org/dc/elements/1.1/In PDF document text
- http://ns.adobe.com/pdf/1.3/In PDF document text
- http://ns.adobe.com/xap/1.0/In PDF document text
- http://ns.adobe.com/xap/1.0/mm/In PDF document text
- http://ns.adobe.com/xap/1.0/rights/In PDF document text
- http://scripts.sil.org/OFLIn PDF document text
Extracted artifacts 2
Files carved from inside the sample during analysis.
| Filename | Kind | Source | Size |
|---|---|---|---|
font_00_sfnt_off0000cd44.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xCD44 | 5344 bytes |
SHA-256: 95e452dbb0ae7ea233a7d36b4e01a5273ab83d0bd140717ca5530a73036f4c4c |
|||
font_01_sfnt_off0000df45.bin |
pdf-font-stream | PDF embedded font (sfnt) at offset 0xDF45 | 10200 bytes |
SHA-256: f4bdaaddffe7afcd25c08092691d4d56a13b8fde141953cd8480a070f0c2f369 |
|||
Open this report in the interactive analyzer, or submit your own file for analysis.